Strategic roadmap

SaaS ERP + AI + BI

Architecture and implementation of a multi-tenant cloud ERP — from data isolation to the tax engine, from artificial intelligence to the experience of the people who run it every day.

A SaaS ERP demands a solid foundation. The intersection of Data Engineering, Data Analysis and Web Design is the tripod that holds up a scalable, intelligent platform with high adoption — the solidity of enterprise architectures with the agility of modern clouds.

Study plan and technical requirements · Complete edition

The roadmap

Nine fronts to build

Each front carries its objective, what to study and what must be drawn before it becomes code.

01

Multi-tenant architecture fundamentals

Scale, security and data isolation in the cloud: Database-per-Tenant, Schema-per-Tenant and Shared Schema patterns; Row-Level Security in PostgreSQL; connection pools and per-transaction context injection (SET LOCAL). To draw: the request flow and practical violation tests — which exist to prove RLS actually holds.

02

Security and access control (RBAC)

Identity for people who work across several companies: global authentication schemas kept apart from tenant schemas, JWT with asymmetric keys (RS256), dual token (access in memory, refresh in an HttpOnly cookie) and dynamic RBAC in the payload. To draw: the ERD from the global table to the permissions join, and the access matrix per module.

03

Advanced security and cryptography

Confidentiality against leaks and interception: TLS 1.3 in transit and AES-256 at rest (disk and database); a KMS for secrets and for rotating the keys that open logistics and financial integrations; masking of sensitive data in the interface itself. To draw: the network architecture (VPC, private subnets) and the end-to-end encryption flow.

04

Audit trail and traceability

An immutable history of every critical action, through Event Sourcing or Change Data Capture: who, when, from where (IP) and what. It is what sustains compliance and regulatory validation — technical dossiers and filings under ANVISA RDC 751/2022, for instance. To draw: the immutable log table, with long-term retention in cold storage.

05

Accounting and tax management

Double-entry bookkeeping for the integrity of every entry; a chart of accounts fit to the tax regime; a dynamic engine ready for the transition from PIS, COFINS, ICMS and ISS towards IBS and CBS (Brazilian tax reform, LC 214/2025); and automated contract adjustments by index. To draw: the tax rule engine and the automated income statement.

06

Business Intelligence integration

Management decisions without punishing the transactional database: OLTP to OLAP replication, 30/60/90-day cash predictability with interest, and cost dashboards consolidating logistics times and amounts. To draw: interactive embedded BI with the consolidated analytical view.

07

Artificial intelligence orchestration

AI as an isolated cognitive engine: Gemini, Claude and Google Antigravity integrated through API orchestration; RAG with strict tenant_id isolation, so one company's knowledge never contaminates another's; proposal drafting, analysis of complex contracts (smart city, solar energy) and support for tariff-code conversion. To draw: the AI micro-interactions on screen — a “Generate proposal” button inside the sales module.

08

Continuity: backup, restore, import and export

Data survival and interoperability with legacy systems: defined RPO and RTO, PITR in PostgreSQL to return to the second before the failure, and asynchronous processing on queues (RabbitMQ, Redis, Celery). Chunking to ingest whole catalogues and tariff tables, or to export heavy routing and insurance batches to carriers, without timing out the web connection. To draw: the background workers and live progress over WebSockets.

09

Web design and user experience

Delivering all those layers in a fluid, low-friction interface: a SaaS-oriented design system and an information architecture that hides fiscal, accounting and cryptographic complexity behind guided flows. To draw: screen transitions, progress indicators for long imports and responsive dashboards.

The tripod

Three disciplines, one ecosystem

An ERP rarely fails for lack of features: it fails through instability, through producing no decisions, or because nobody can stand using it.

Data engineering

The engine and the cloud: multi-tenant database and infrastructure with strict isolation; microservices that bring AI into the sales flow and connectors for payment gateways, carriers (freight, reverse logistics, tariff codes) and invoicing; and heavy routines — 30/60/90 billing with interest, subscription renewals — running in the background without holding the interface.

Data analysis

The business intelligence that turns the ERP from a record keeper into a decision tool: modelling Brazilian tax rules (today's regime and the IBS/CBS transition), dashboards consolidating logistics bottlenecks, sales conversion and real-time cash forecasting, and governance that automates technical documents — indexed lease contracts, regulatory dossiers — free of human error.

Web design and UI/UX

The experience of whoever operates it: a consistent design system so HR, sales and finance speak the same visual language; continuous journeys that turn long processes into step-by-step wizards, such as commercial proposals and import records; and responsiveness where it truly matters — approvals and KPIs on the phone, back office on the desktop.

SaaS integration map

Who delivers what

Harmony across the three fronts is what gives the software the stability not to fail, the intelligence to add value and the usability to retain customers over the long run.

DisciplineMain SaaS focusCritical deliverable
Data engineeringScalability, integrations and cloudMulti-tenant backend, API and LLM orchestration
Data analysisBusiness logic, BI and taxesPredictive dashboards, tax and financial modelling
Web design (UI/UX)Usability, retention and frontendDesign system, screens and intuitive journeys

The foundation

Multi-tenant isolation: three paths

The choice dictates cloud cost and the ability to run heavy routines without one customer freezing everyone else's system — the noisy neighbour effect.

Silo · database per tenant

Each company on its own physical instance. Maximum isolation and excellent individual performance: a giant customer's tax closing never disturbs the smaller ones. The price is scale: 500 customers become 500 databases to upgrade and back up.

Bridge · schema per tenant

One database, one schema per company — separate folders on the same disk. High isolation, which prevents leaks from a badly written query, and single-customer restores. The price is migration: a new column for the tax reform must run in every schema.

Pool · fully shared

The same tables for everyone, separated by a tenant_id column. Minimum cost, maximum scale and one structural change applying to all at once — the pattern used by the SaaS giants. The price is rigour: without control, one customer's heavy report eats the database CPU and slows the ERP for the rest.

For a complex B2B ERP, schema per tenant is usually the safest starting point. For massive volume, the shared model with Row-Level Security in PostgreSQL is the road to growth — and there the performance secret is messaging (RabbitMQ, Kafka) pushing every heavy calculation into the background, freeing the database at once.

From roadmap to system

This roadmap covers advanced security, cryptography, audit trails, accounting compliance, backup and restore, and asynchronous processing of large volumes. It is the same rigour Passos applies to the systems already running its own house — portal, e-commerce, tax documents and logistics.